Privacy Policy — TapScanner (Web + Mobile)

Last updated: July 31, 2026

Applies to: tap‑scanner.com and subdomains, the TapScanner mobile apps (iOS/Android), and customer support channels (collectively, the “Services”).

Who we are

Controller: Smart media internet marketing ltd., Torat hayahasut 11, Israel (“Tap”, “we”, “us”).

Email (privacy): [email protected]

If you buy a web subscription, your purchase is processed by Paddle as Merchant of Record; your contract for checkout/billing is with Paddle.com (Paddle.com Market Ltd. or Paddle.com Inc.) per Paddle’s Buyer Terms. Paddle acts as an independent controller for buyer/payment data.

At a glance

We process files you upload only to provide the requested tools (e.g., compress, merge, OCR). Temporary-file handling varies by tool; current implementation-backed details and limits are published on our Trust and file processing page.

Mobile: scanning, on‑device edits, and many effects can run locally; features that use hosted OCR, AI, storage, or sharing may send content to a service provider as described by that feature.

Payments on the web are handled by Paddle; we do not receive or store full card numbers. See Paddle’s Privacy Policy and Buyer Terms for checkout data.

Privacy rights requests can be sent to [email protected].

1. What we collect

  • Account & Contact. Name, email, password hash, team/org info (if applicable), settings, support messages.
  • Payment & Subscription (Web). Order ID, subscription status, plan, country/tax info, and the last 4 digits/expiry via Paddle. Paddle collects payment instrument data directly and provides us with non‑sensitive billing metadata.
  • Files & Content. PDFs, images, and related metadata (e.g., file type/size, page count) that you upload or scan to use the tools.
  • Device/Usage. Device model/OS, app version, coarse IP‑based region, timestamps, crash/diagnostic events, feature engagement, and web telemetry (cookies/SDKs) for security and product improvement.
  • Social/SSO (optional). If you sign in with Apple/Google/Facebook, we receive your basic profile and email from those platforms.
  • Advertising (mobile free tier, if enabled). Mobile ad identifiers and limited device/usage signals to show and measure ads in free versions.
  • Sensitive files. Please do not upload regulated or highly sensitive personal data (e.g., payment cards, health/biometric data, government IDs) unless a tool explicitly supports it and you are legally allowed to process it.

2. Why we process your data (and legal bases)

  • Provide the Services & features (including file processing, OCR, compression, conversion, sync): contract (GDPR Art. 6(1)(b)).
  • Payments, tax, invoices (via Paddle) and compliance: legal obligation (Art. 6(1)(c)) and contract.
  • Security, abuse prevention, service reliability (e.g., fraud, anti‑abuse, rate limiting): legitimate interests (Art. 6(1)(f)).
  • Improve the product & support (diagnostics, analytics, A/B tests): legitimate interests (Art. 6(1)(f)).
  • Marketing emails, optional cookies, AI quality‑improvement opt‑ins: consent (Art. 6(1)(a)).

Where legally required and available, applicable consent or opt‑out controls will be provided.

3. File processing & retention

Transient processing. Web tools use temporary storage when needed. On normal response paths in the current core, an output temporary file is removed when its download stream closes, and scheduled cleanup covers stale temporary files. We do not publish a guaranteed maximum deletion window for every tool unless a tool-specific notice says otherwise.

Account storage. If a feature explicitly offers account storage and you choose it, we retain the file until you delete it or your account is deleted.

Processing location. Web tools may send files to TapScanner's hosted processing service. We do not currently offer a customer-selectable processing region; do not assume a web operation stays on your device or in a particular country unless the tool explicitly says so.

Mobile specifics. Many edits stay on-device. Images sent to hosted effects or OCR are handled according to the feature-specific notice and the provider terms that apply to that feature.

Backups & logs. Operational logs and backup copies are retained only as needed for service operation, fraud prevention, legal obligations, and dispute handling. A specific window is stated only where it has been verified for that system.

4. Sharing your data

We do not sell your personal information for money. In limited contexts (ads/analytics), we may “share” identifiers for cross‑context behavioral advertising where permitted by law. We share data only with:

  • Payment processor & Merchant of Record – Paddle (checkout, VAT/GST, refunds, fraud screening). See Paddle’s Privacy Policy / Buyer Terms.
  • Cloud hosting/CDN & compute providers used for processing and delivery.
  • Analytics/crash/telemetry to operate and improve the Service.
  • AI infrastructure providers only when you choose a feature that requires them, subject to the notice and terms for that feature.
  • Support tools & email providers to handle tickets/notifications.
  • Legal/Compliance (e.g., to comply with law, enforce terms, defend rights).

We require processors to follow our instructions, apply appropriate security, and not use data for their own purposes.

5. Cookies & tracking (web)

Essential cookies keep authentication, subscription checks, fraud prevention, and PDF workflows operating. They remain available when optional measurement is declined.

If you grant permission, we use Google Tag Manager with Google Analytics and Google Ads destinations to measure page visits, tool funnel steps, login, checkout, and verified subscription events. Optional measurement may use campaign parameters and Google click identifiers. We do not send filenames or document contents to these services.

Your choice is shared across tap‑scanner.com and tools.tap‑scanner.com for up to 180 days. You can change it at any time through the “Privacy settings” link in the site footer. Privacy rights requests can be sent to [email protected].

6. International transfers

We operate globally using reputable providers. When transferring personal data internationally, we use legal safeguards such as the EU Standard Contractual Clauses (SCCs) and, for UK data, the UK IDTA / UK Addendum.

7. Security

We use administrative, technical, and organizational measures designed for the risks of the Services. The public Trust and file processing page lists only current implementation facts that have a dated evidence source; it does not imply a certification.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, export, or object/limit processing. To exercise rights, contact [email protected].

EEA/UK users. You can withdraw consent anytime; you may complain to your local supervisory authority.

US residents. See US State Privacy Notice (below). Requests to exercise applicable opt‑out rights can be sent to [email protected].

9. Minors

The Services are not directed to children under 13. In the EEA/UK, you must meet the applicable digital‑consent age in your country or have verifiable parental consent.

10. US State Privacy Notice (CPRA, CPA, TDPSA, etc.)

We disclose the categories of data described in §1.

  • California residents may have rights to access, delete, correct, and opt out of certain sale/share activities.
  • Colorado residents may have rights to access, delete, correct, portability, and to opt out of targeted advertising or certain sales.
  • For Texas residents (TDPSA), you have rights to access, delete, correct, portability, and to opt‑out of targeted advertising/sale/profiling.

Submit requests to [email protected]. Additional controls will be provided where legally required and available.

11. Data retention

We keep personal data only as long as necessary for the purposes above:

  • Files in web processing: temporary-file handling varies by tool; no universal maximum deletion window is promised. See the current implementation-backed lifecycle statement on the Trust page.
  • Account storage: where a feature explicitly offers it, until you delete the file or close the account.
  • Billing/tax records: 10 years or as required by law.
  • Backups/logs: only as long as needed for the stated operational, fraud-prevention, legal, and dispute-handling purposes; system-specific windows are published only after verification.

12. Changes

We’ll post changes here and, if material, notify you in‑app/email.

13. Contact

Smart media internet marketing ltd.
Address: Torat hayahasut 11, Beer Sheva, Israel
Email: [email protected]
Data Protection Officer + EU/UK Representative : [email protected]

Privacy settings

Review optional product analytics and advertising measurement choices. Essential cookies for login, payments, and PDF tools stay enabled.

Current web-processing facts

  • Hosted processing paths may use temporary files. In the pinned core's normal download path, the output file is removed when the stream closes; scheduled cleanup covers stale temporary files.
  • Web tools may send files to TapScanner's hosted processing service. We do not currently offer a customer-selectable processing region, so do not assume processing stays on your device or in a particular country.
  • Delete-now is available only when a result screen explicitly offers it; it is not yet supported by every web tool.
See evidence dates and explicit limits

Saved Cloud Documents are different from temporary processing

A PDF appears in Cloud Documents only when a signed-in customer explicitly saves or uploads it. Saved documents remain tied to that TapScanner account until the customer uses Delete now; they are not covered by the shorter temporary-processing lifecycle shown above.

Downloads use short-lived links. Deleting a saved document removes the storage object rather than merely hiding it from the list.

Privacy Policy | TapScanner